Description
In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 12 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox. | |
| First Time appeared |
Flatpak
Flatpak flatpak |
|
| Weaknesses | CWE-61 | |
| CPEs | cpe:2.3:a:flatpak:flatpak:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flatpak
Flatpak flatpak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-12T20:00:58.476Z
Reserved: 2026-09-12T20:00:58.046Z
Link: CVE-2026-90616
No data.
Status : Received
Published: 2026-09-12T20:16:30.957
Modified: 2026-09-12T20:16:30.957
Link: CVE-2026-90616
No data.
OpenCVE Enrichment
No data.
Weaknesses